3 ms·
Do most DNS forwarders not block addresses that resolve to a local IP these days? I know dnsmasq does, and NextDNS too I think.
by wrboyce 3y ago
Do most DNS forwarders not block addresses that resolve to a local IP these days? I know dnsmasq does, and NextDNS too I think.
- donmcronald 3y agoI think most will see it as a DNS rebinding attack [1]. 1. https://en.wikipedia.org/wiki/DNS_rebinding https://en.wikipedia.org/wiki/DNS_rebinding
- wrboyce 3y agoThat’s the phrase I was looking for!
- drexlspivey 3y agoWhy? Having local IPs on a public DNS is a legitimate use case.
- wolverine876 3y agoIn fact, some people block domains by routing them to 127.0.0.1 in their host files. I've used private ranges too, in places where loopback might possibly do something funky.
- wrboyce 3y agoAs another reply mentioned, to prevent DNS rebinding attacks. The general expectation is you will whitelist domains from which you expect RFC1918 responses.